Skip to main content

Advanced assurance functions

These modules extend the same application, evidence and receipt model. They are entitlement- and policy-controlled.

Passport NFC

The iOS and Android SDKs can read ICAO 9303 passport chips using supported PACE/BAC flows. Native capture returns DG1, DG2, SOD, document-signer and chip-authentication evidence. Assayra verifies data-group hashes, SOD signature and configured CSCA trust server-side; the mobile app cannot assert authenticity.

Digital wallets

Assayra supports OpenID4VP presentations, OpenID4VCI issuance, SD-JWT VC and ISO mdoc paths. Trust anchors, credential configuration, holder binding, request binding and status are governed tenant-side.

Proof Packages

A Proof Package provides a privacy-minimised, signed presentation of selected application/receipt claims. It binds purpose, audience and expiry so a relying party can verify the package without receiving every underlying evidence object.

Attended verification

Create a scheduled session linked to an application. Reviewer identity, applicant consent, call state, observations and evidence actions are recorded. Configure a production TURN service for restrictive networks and never treat the media server as an evidence store.

Agent assurance

Register an autonomous workload using its public JWK, bind it to a principal and issue a constrained mandate: allowed actions, resource prefixes, value/currency limits, jurisdictions, expiry and rate. Signed action requests use JTI replay defence and generate action receipts.

Assurance Graph

The graph stores temporal typed relationships between subjects, evidence, devices, businesses, risks and decisions with provenance. Use it for explainable investigations and resolution—not for leaking one tenant’s raw identity into another.

Optimizer

The Assurance Optimizer can select an approved route using assurance, cost, latency, country and channel constraints. It cannot remove controls mandatory in the workflow or Country Assurance Pack.